T08 · Insecure Dependencies
- Location
SKILL.md:55- Finding
Unpinned npm Package Is Downloaded and Executed Automatically
- Content
View full analysis
- Remediation
View remediation
`. 2. Use a lockfile and package integrity hashes to ensure reproducible dependency resolution. 3. Prefer a locally installed or vendored dependency over downloading executable code at Skill startup. 4. Remove `-y` where practical so first-time installation requires explicit user approval. 5. Disable npm lifecycle scripts when they are unnecessary, such as by installing with `--ignore-scripts` after verifying compatibility. 6. Review package provenance, maintainer activity, release signatures, and published contents before upgrading. 7. Test upgrades in an isolated environment and update the pinned version only after security review. 8. Run the MCP process with least privilege and restrict its access to sensitive files, credentials, and network resources. ]]>
